Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-9650. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit leverages an authenticated arbitrary file upload vulnerability in Automated Logic WebCTRL 6.5 and prior versions. It uploads a malicious WAR file via the 'uploadwarfile' servlet, bypassing improper authorization checks, leading to remote code execution.
Description
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to upload a malicious file allowing the execution of arbitrary code.
Exploits (1)
This exploit leverages an authenticated arbitrary file upload vulnerability in Automated Logic WebCTRL 6.5 and prior versions. It uploads a malicious WAR file via the 'uploadwarfile' servlet, bypassing improper authorization checks, leading to remote code execution.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H